Skip to content

x/vulndb: potential Go vuln in github.com/mattermost/mattermost/server/v8: GHSA-7h34-9chr-58qh #3819

@GoVulnBot

Description

@GoVulnBot

Advisory GHSA-7h34-9chr-58qh references a vulnerability in the following Go modules:

Module
github.com/mattermost/mattermost-server
github.com/mattermost/mattermost-server/v5
github.com/mattermost/mattermost-server/v6
github.com/mattermost/mattermost/server/v8

Description:
Mattermost versions 10.5.x <= 10.5.6, 10.8.x <= 10.8.1, 10.7.x <= 10.7.3, 9.11.x <= 9.11.16 fail to verify authorization when retrieving cached posts by PendingPostID which allows an authenticated user to read posts in private channels they don't have access to via guessing the PendingPostID of recently created posts.

References:

Cross references:

See doc/quickstart.md for instructions on how to triage this report.

id: GO-ID-PENDING
modules:
    - module: github.com/mattermost/mattermost-server
      versions:
        - introduced: 9.11.0+incompatible
        - fixed: 9.11.17+incompatible
        - introduced: 10.5.0+incompatible
        - fixed: 10.5.7+incompatible
        - introduced: 10.7.0+incompatible
        - fixed: 10.7.4+incompatible
        - introduced: 10.8.0+incompatible
        - fixed: 10.8.2+incompatible
      vulnerable_at: 10.8.1+incompatible
    - module: github.com/mattermost/mattermost-server/v5
      vulnerable_at: 5.39.3
    - module: github.com/mattermost/mattermost-server/v6
      vulnerable_at: 6.7.2
    - module: github.com/mattermost/mattermost/server/v8
      versions:
        - fixed: 8.0.0-20250520130510-fa40a8c5d47f
summary: Mattermost Missing Authentication for Critical Function in github.com/mattermost/mattermost-server
cves:
    - CVE-2025-6226
ghsas:
    - GHSA-7h34-9chr-58qh
references:
    - advisory: https://github.com/advisories/GHSA-7h34-9chr-58qh
    - advisory: https://nvd.nist.gov/vuln/detail/CVE-2025-6226
    - fix: https://github.com/mattermost/mattermost/commit/fa40a8c5d47fed5c166429a1c1bd95d62b241d89
    - web: https://mattermost.com/security-updates
notes:
    - fix: 'github.com/mattermost/mattermost/server/v8: could not add vulnerable_at: could not find tagged version between introduced and fixed'
source:
    id: GHSA-7h34-9chr-58qh
    created: 2025-07-21T19:04:02.501527971Z
review_status: UNREVIEWED

Metadata

Metadata

Labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions